Combo fix log:
ComboFix 11-12-28.03 - Tad Palmer 12/28/2011 20:21:35.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1570 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((( Files Created from 2011-11-28 to 2011-12-29 )))))))))))))))))))))))))))))))
.
.
2011-12-29 01:12 . 2007-02-16 02:20 139776 ----a-w- c:\program files\Mozilla Firefox\Desktop\FixPolicies\swreg.exe
2011-12-28 21:06 . 2011-12-28 21:06 29904 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0DC8B2AD-4956-48B0-A93F-B4896B3F93D6}\MpKslcdfa53d0.sys
2011-12-28 21:05 . 2011-12-28 21:05 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0DC8B2AD-4956-48B0-A93F-B4896B3F93D6}\offreg.dll
2011-12-28 21:05 . 2011-11-21 07:47 6823496 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0DC8B2AD-4956-48B0-A93F-B4896B3F93D6}\mpengine.dll
2011-12-27 20:37 . 2011-12-27 20:37 193024 -c--a-w- c:\windows\system32\dllcache\fsquirt.exe
2011-12-27 20:37 . 2011-12-27 20:37 193024 ----a-w- c:\windows\system32\fsquirt.exe
2011-12-27 14:14 . 2011-12-27 14:14 -------- d-----w- c:\program files\Common Files\Java
2011-12-27 14:14 . 2011-12-27 14:14 141312 ----a-w- c:\windows\system32\javacpl.cpl
2011-12-27 14:14 . 2011-12-27 14:13 637848 ----a-w- c:\windows\system32\npdeployJava1.dll
2011-12-27 14:13 . 2011-12-27 14:13 -------- d-----w- c:\program files\Java
2011-12-25 02:46 . 2011-11-21 07:47 6823496 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-12-23 09:42 . 2009-08-07 00:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2011-12-23 09:42 . 2009-08-07 00:23 215920 ----a-w- c:\windows\system32\muweb.dll
2011-12-23 01:58 . 2010-10-19 20:51 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-12-23 01:50 . 2011-12-23 01:51 -------- d-----w- c:\program files\Microsoft Security Client
2011-12-20 22:24 . 2011-08-31 22:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-20 22:24 . 2011-12-20 22:24 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-12-17 19:40 . 2011-12-23 19:51 -------- d-----w- c:\documents and settings\Tad Palmer\Local Settings\Application Data\Google
2011-12-14 19:02 . 2011-12-14 19:02 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2011-12-13 16:03 . 2011-12-13 16:03 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-27 14:13 . 2011-10-11 00:34 567184 ----a-w- c:\windows\system32\deployJava1.dll
2011-11-23 13:25 . 2008-04-14 05:00 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-04 19:20 . 2008-04-14 09:42 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-11-04 19:20 . 2008-04-14 09:42 916992 ----a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2008-04-14 09:41 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-11-04 11:23 . 2008-04-14 04:07 385024 ----a-w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2008-04-14 09:42 1288704 ----a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2008-04-14 09:41 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:33 . 2008-04-14 04:57 2192768 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2008-04-14 04:01 2069376 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13 . 2008-04-14 09:41 186880 ----a-w- c:\windows\system32\encdec.dll
2011-10-11 00:41 . 2011-10-11 00:41 21425 ----a-w- c:\windows\system32\drivers\AegisP.sys
2011-10-10 14:22 . 2011-10-10 23:31 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-11-09 14:47 . 2011-10-11 00:03 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-05-10 . 6460FBE53566E18B9B07EDCAD804FBE5 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2011-12-14_18.42.13 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-04-19 03:51 . 2011-04-19 03:51 51024 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_4ddc769f\vcomp90.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90rus.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90kor.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90jpn.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90ita.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90fra.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90esp.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90esn.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 53584 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90enu.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 63312 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90deu.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90cht.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 35664 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90chs.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfcm90u.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfcm90.dll
+ 2011-05-14 01:17 . 2011-05-14 01:17 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_452bf920\vcomp.dll
+ 2011-05-14 00:45 . 2011-05-14 00:45 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80KOR.dll
+ 2011-05-14 00:45 . 2011-05-14 00:45 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80JPN.dll
+ 2011-05-14 00:45 . 2011-05-14 00:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ITA.dll
+ 2011-05-14 00:45 . 2011-05-14 00:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80FRA.dll
+ 2011-05-14 00:45 . 2011-05-14 00:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ESP.dll
+ 2011-05-14 00:45 . 2011-05-14 00:45 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ENU.dll
+ 2011-05-14 00:45 . 2011-05-14 00:45 65536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80DEU.dll
+ 2011-05-14 00:45 . 2011-05-14 00:45 45056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80CHT.dll
+ 2011-05-14 00:45 . 2011-05-14 00:45 40960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80CHS.dll
+ 2011-05-14 06:06 . 2011-05-14 06:06 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfcm80u.dll
+ 2011-05-14 06:23 . 2011-05-14 06:23 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfcm80.dll
+ 2011-05-13 23:37 . 2011-05-13 23:37 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_a4c618fa\ATL80.dll
+ 2011-12-27 21:00 . 2011-12-27 21:00 16384 c:\windows\temp\Perflib_Perfdata_568.dat
+ 2008-04-14 09:42 . 2011-11-04 19:20 66560 c:\windows\system32\mshtmled.dll
- 2008-04-14 09:42 . 2011-08-22 23:48 66560 c:\windows\system32\mshtmled.dll
+ 2009-03-08 08:31 . 2011-11-04 19:20 55296 c:\windows\system32\msfeedsbs.dll
- 2009-03-08 08:31 . 2011-08-22 23:48 55296 c:\windows\system32\msfeedsbs.dll
- 2008-04-14 09:41 . 2011-08-22 23:48 25600 c:\windows\system32\jsproxy.dll
+ 2008-04-14 09:41 . 2011-11-04 19:20 25600 c:\windows\system32\jsproxy.dll
+ 2011-10-11 01:02 . 2011-11-04 19:20 12800 c:\windows\system32\dllcache\xpshims.dll
- 2011-10-11 01:02 . 2011-08-22 23:48 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2008-04-14 09:42 . 2011-11-04 19:20 66560 c:\windows\system32\dllcache\mshtmled.dll
- 2008-04-14 09:42 . 2011-08-22 23:48 66560 c:\windows\system32\dllcache\mshtmled.dll
+ 2011-10-11 01:02 . 2011-11-04 19:20 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2011-10-11 01:02 . 2011-08-22 23:48 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2008-04-14 09:41 . 2011-08-22 23:48 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2008-04-14 09:41 . 2011-11-04 19:20 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2008-04-14 09:41 . 2011-11-04 19:20 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2008-04-14 09:41 . 2011-08-22 23:48 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2008-04-14 09:41 . 2011-10-28 05:31 33280 c:\windows\system32\dllcache\csrsrv.dll
- 2008-04-14 09:41 . 2011-04-26 11:07 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2011-10-10 23:33 . 2011-12-17 00:22 86327 c:\windows\pchealth\helpctr\OfflineCache\index.dat
- 2011-10-10 23:33 . 2011-10-10 23:33 86327 c:\windows\pchealth\helpctr\OfflineCache\index.dat
+ 2011-12-15 09:34 . 2011-08-22 23:48 12800 c:\windows\ie8updates\KB2618444-IE8\xpshims.dll
+ 2011-12-15 09:34 . 2011-08-22 23:48 66560 c:\windows\ie8updates\KB2618444-IE8\mshtmled.dll
+ 2011-12-15 09:34 . 2011-08-22 23:48 55296 c:\windows\ie8updates\KB2618444-IE8\msfeedsbs.dll
+ 2011-12-15 09:34 . 2011-08-22 23:48 43520 c:\windows\ie8updates\KB2618444-IE8\licmgr10.dll
+ 2011-12-15 09:34 . 2011-08-22 23:48 25600 c:\windows\ie8updates\KB2618444-IE8\jsproxy.dll
+ 2011-10-10 23:33 . 2011-12-17 00:22 2850 c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
+ 2011-04-19 03:51 . 2011-04-19 03:51 653136 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcr90.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 569680 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcp90.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcm90.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 159048 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_92453bb7\atl90.dll
+ 2011-05-14 06:17 . 2011-05-14 06:17 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcr80.dll
+ 2011-05-14 06:12 . 2011-05-14 06:12 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcp80.dll
+ 2011-05-14 06:11 . 2011-05-14 06:11 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcm80.dll
- 2008-04-14 09:42 . 2011-08-22 23:48 105984 c:\windows\system32\url.dll
+ 2008-04-14 09:42 . 2011-11-04 19:20 105984 c:\windows\system32\url.dll
+ 2008-04-14 09:42 . 2011-11-04 19:20 206848 c:\windows\system32\occache.dll
- 2008-04-14 09:42 . 2011-08-22 23:48 206848 c:\windows\system32\occache.dll
+ 2008-04-14 09:42 . 2011-11-04 19:20 611840 c:\windows\system32\mstime.dll
- 2008-04-14 09:42 . 2011-08-22 23:48 611840 c:\windows\system32\mstime.dll
+ 2009-03-08 08:32 . 2011-11-04 19:20 602112 c:\windows\system32\msfeeds.dll
- 2009-03-08 08:32 . 2011-08-22 23:48 602112 c:\windows\system32\msfeeds.dll
+ 2011-12-27 14:14 . 2011-12-27 14:14 223112 c:\windows\system32\javaws.exe
+ 2011-12-27 14:14 . 2011-12-27 14:14 173960 c:\windows\system32\javaw.exe
+ 2011-12-27 14:14 . 2011-12-27 14:14 173960 c:\windows\system32\java.exe
+ 2008-04-14 09:41 . 2011-11-04 19:20 184320 c:\windows\system32\iepeers.dll
- 2008-04-14 09:41 . 2011-08-22 23:48 184320 c:\windows\system32\iepeers.dll
+ 2008-04-14 09:41 . 2011-11-04 19:20 387584 c:\windows\system32\iedkcs32.dll
- 2008-04-14 09:41 . 2011-08-22 23:48 387584 c:\windows\system32\iedkcs32.dll
+ 2008-04-14 09:42 . 2011-11-04 11:24 174080 c:\windows\system32\ie4uinit.exe
- 2008-04-14 09:42 . 2011-08-22 11:56 174080 c:\windows\system32\ie4uinit.exe
+ 2011-10-10 19:23 . 2011-12-15 12:36 135664 c:\windows\system32\FNTCACHE.DAT
- 2011-10-10 19:23 . 2011-10-13 09:10 135664 c:\windows\system32\FNTCACHE.DAT
+ 2011-04-18 18:18 . 2011-04-18 18:18 165648 c:\windows\system32\drivers\MpFilter.sys
+ 2008-04-14 09:42 . 2011-11-04 19:20 916992 c:\windows\system32\dllcache\wininet.dll
- 2008-04-14 09:42 . 2011-08-22 23:48 105984 c:\windows\system32\dllcache\url.dll
+ 2008-04-14 09:42 . 2011-11-04 19:20 105984 c:\windows\system32\dllcache\url.dll
- 2008-04-14 09:42 . 2011-08-22 23:48 206848 c:\windows\system32\dllcache\occache.dll
+ 2008-04-14 09:42 . 2011-11-04 19:20 206848 c:\windows\system32\dllcache\occache.dll
+ 2008-04-14 09:42 . 2011-11-04 19:20 611840 c:\windows\system32\dllcache\mstime.dll
- 2008-04-14 09:42 . 2011-08-22 23:48 611840 c:\windows\system32\dllcache\mstime.dll
+ 2011-10-11 01:02 . 2011-11-04 19:20 602112 c:\windows\system32\dllcache\msfeeds.dll
- 2011-10-11 01:02 . 2011-08-22 23:48 602112 c:\windows\system32\dllcache\msfeeds.dll
+ 2011-10-11 01:02 . 2011-11-04 19:20 247808 c:\windows\system32\dllcache\ieproxy.dll
- 2011-10-11 01:02 . 2011-08-22 23:48 247808 c:\windows\system32\dllcache\ieproxy.dll
- 2008-04-14 09:41 . 2011-08-22 23:48 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2008-04-14 09:41 . 2011-11-04 19:20 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2011-10-11 01:02 . 2011-11-04 19:20 743424 c:\windows\system32\dllcache\iedvtool.dll
- 2011-10-11 01:02 . 2011-08-22 23:48 743424 c:\windows\system32\dllcache\iedvtool.dll
- 2008-04-14 09:41 . 2011-08-22 23:48 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-04-14 09:41 . 2011-11-04 19:20 387584 c:\windows\system32\dllcache\iedkcs32.dll
- 2008-04-14 09:42 . 2011-08-22 11:56 174080 c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-04-14 09:42 . 2011-11-04 11:24 174080 c:\windows\system32\dllcache\ie4uinit.exe
- 2008-04-14 09:41 . 2011-02-09 13:53 186880 c:\windows\system32\dllcache\encdec.dll
+ 2008-04-14 09:41 . 2011-10-18 11:13 186880 c:\windows\system32\dllcache\encdec.dll
+ 2011-12-27 14:14 . 2011-12-27 14:14 176128 c:\windows\Installer\df630.msi
+ 2011-12-27 14:13 . 2011-12-27 14:13 938496 c:\windows\Installer\df62b.msi
+ 2011-12-23 01:51 . 2011-12-23 01:51 785920 c:\windows\Installer\840ad.msi
+ 2011-12-23 01:51 . 2011-12-23 01:51 483840 c:\windows\Installer\840a7.msi
+ 2011-12-23 01:50 . 2011-12-23 01:50 301056 c:\windows\Installer\840a2.msi
+ 2011-12-23 10:11 . 2011-12-23 10:11 223744 c:\windows\Installer\1d1c145.msi
+ 2011-12-23 10:11 . 2011-12-23 10:11 467456 c:\windows\Installer\1d1c13f.msi
+ 2011-12-15 09:34 . 2011-08-22 23:48 916480 c:\windows\ie8updates\KB2618444-IE8\wininet.dll
+ 2011-12-15 09:34 . 2011-08-22 23:48 105984 c:\windows\ie8updates\KB2618444-IE8\url.dll
+ 2011-12-15 09:34 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2618444-IE8\spuninst\updspapi.dll
+ 2011-12-15 09:34 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2618444-IE8\spuninst\spuninst.exe
+ 2011-12-15 09:34 . 2011-08-22 23:48 206848 c:\windows\ie8updates\KB2618444-IE8\occache.dll
+ 2011-12-15 09:34 . 2011-08-22 23:48 611840 c:\windows\ie8updates\KB2618444-IE8\mstime.dll
+ 2011-12-15 09:34 . 2011-08-22 23:48 602112 c:\windows\ie8updates\KB2618444-IE8\msfeeds.dll
+ 2011-12-15 09:34 . 2011-08-22 23:48 247808 c:\windows\ie8updates\KB2618444-IE8\ieproxy.dll
+ 2011-12-15 09:34 . 2011-08-22 23:48 184320 c:\windows\ie8updates\KB2618444-IE8\iepeers.dll
+ 2011-12-15 09:34 . 2011-08-22 23:48 743424 c:\windows\ie8updates\KB2618444-IE8\iedvtool.dll
+ 2011-12-15 09:34 . 2011-08-22 23:48 387584 c:\windows\ie8updates\KB2618444-IE8\iedkcs32.dll
+ 2011-12-15 09:34 . 2011-08-22 11:56 174080 c:\windows\ie8updates\KB2618444-IE8\ie4uinit.exe
+ 2011-12-23 19:46 . 2011-12-23 19:46 262144 c:\windows\ERDNT\12-23-2011\Users\00000002\UsrClass.dat
+ 2011-12-23 19:46 . 2005-10-20 16:02 163328 c:\windows\ERDNT\12-23-2011\ERDNT.EXE
+ 2011-04-19 03:51 . 2011-04-19 03:51 3781960 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90u.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 3766600 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90.dll
+ 2011-05-14 01:04 . 2011-05-14 01:04 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfc80u.dll
+ 2011-05-14 01:04 . 2011-05-14 01:04 1101824 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfc80.dll
- 2008-04-14 09:42 . 2011-08-22 23:48 1212416 c:\windows\system32\urlmon.dll
+ 2008-04-14 09:42 . 2011-11-04 19:20 1212416 c:\windows\system32\urlmon.dll
+ 2008-04-14 09:42 . 2011-11-04 19:20 5978112 c:\windows\system32\mshtml.dll
- 2009-03-08 08:32 . 2011-08-22 23:48 2000384 c:\windows\system32\iertutil.dll
+ 2009-03-08 08:32 . 2011-11-04 19:20 2000384 c:\windows\system32\iertutil.dll
+ 2008-04-14 05:00 . 2011-11-23 13:25 1859584 c:\windows\system32\dllcache\win32k.sys
- 2008-04-14 09:42 . 2011-08-22 23:48 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2008-04-14 09:42 . 2011-11-04 19:20 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2008-04-14 09:42 . 2011-11-01 16:07 1288704 c:\windows\system32\dllcache\ole32.dll
- 2011-10-11 00:27 . 2010-12-09 13:38 2192768 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2011-10-11 00:27 . 2011-10-25 13:33 2192768 c:\windows\system32\dllcache\ntoskrnl.exe
- 2011-10-11 00:27 . 2010-12-09 13:07 2027008 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2011-10-11 00:27 . 2011-10-25 12:52 2027008 c:\windows\system32\dllcache\ntkrpamp.exe
- 2011-10-11 00:27 . 2010-12-09 13:07 2069376 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2011-10-11 00:27 . 2011-10-25 12:52 2069376 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2011-10-11 00:27 . 2010-12-09 13:42 2148864 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2011-10-11 00:27 . 2011-10-25 13:37 2148864 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2008-04-14 09:42 . 2011-11-04 19:20 5978112 c:\windows\system32\dllcache\mshtml.dll
- 2011-10-11 01:02 . 2011-08-22 23:48 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2011-10-11 01:02 . 2011-11-04 19:20 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2011-10-11 12:19 . 2011-12-14 19:02 9049600 c:\windows\Installer\{BDBAAB1B-B364-465E-931D-4E2E2F0E609A}\{D2B942CC-0565-43C6-82F9-DE26EA4928E6}\HIPS2.msi
- 2011-10-11 12:19 . 2011-10-11 12:19 9049600 c:\windows\Installer\{BDBAAB1B-B364-465E-931D-4E2E2F0E609A}\{D2B942CC-0565-43C6-82F9-DE26EA4928E6}\HIPS2.msi
+ 2011-12-15 09:34 . 2011-08-22 23:48 1212416 c:\windows\ie8updates\KB2618444-IE8\urlmon.dll
+ 2011-12-15 09:34 . 2011-10-03 08:35 5971456 c:\windows\ie8updates\KB2618444-IE8\mshtml.dll
+ 2011-12-15 09:34 . 2011-08-22 23:48 2000384 c:\windows\ie8updates\KB2618444-IE8\iertutil.dll
+ 2011-12-23 19:46 . 2011-12-23 19:46 2924544 c:\windows\ERDNT\12-23-2011\Users\00000001\NTUSER.DAT
+ 2011-10-11 00:27 . 2011-10-25 13:33 2192768 c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2011-10-11 00:27 . 2010-12-09 13:38 2192768 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2011-10-11 00:27 . 2011-10-25 12:52 2027008 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2011-10-11 00:27 . 2010-12-09 13:07 2027008 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2011-10-11 00:27 . 2011-10-25 12:52 2069376 c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2011-10-11 00:27 . 2010-12-09 13:07 2069376 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2011-10-11 00:27 . 2011-10-25 13:37 2148864 c:\windows\Driver Cache\i386\ntkrnlmp.exe
- 2011-10-11 00:27 . 2010-12-09 13:42 2148864 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2011-10-11 00:54 . 2011-12-14 19:28 52988224 c:\windows\system32\MRT.exe
+ 2009-03-08 08:39 . 2011-11-04 19:20 11081728 c:\windows\system32\ieframe.dll
- 2009-03-08 08:39 . 2011-08-23 21:48 11081728 c:\windows\system32\ieframe.dll
- 2011-10-11 01:02 . 2011-08-23 21:48 11081728 c:\windows\system32\dllcache\ieframe.dll
+ 2011-10-11 01:02 . 2011-11-04 19:20 11081728 c:\windows\system32\dllcache\ieframe.dll
+ 2011-12-15 09:34 . 2011-08-23 21:48 11081728 c:\windows\ie8updates\KB2618444-IE8\ieframe.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2008-07-10 29984]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2008-07-10 46368]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
"BrStsMon00"="c:\program files\Browny02\Brother\BrStMonW.exe" [2010-02-09 2621440]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2011-05-15 325512]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2009-03-08 128512]
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
[BU]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiMalware]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2011\\QBDBMgrN.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
.
R1 MpKslcdfa53d0;MpKslcdfa53d0;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0DC8B2AD-4956-48B0-A93F-B4896B3F93D6}\MpKslcdfa53d0.sys [12/28/2011 4:06 PM 29904]
R2 QBVSS;QBIDPService;c:\program files\Common Files\Intuit\DataProtect\QBIDPService.exe [6/30/2011 12:25 PM 1248256]
R3 BrYNSvc;BrYNSvc;c:\program files\Browny02\BrYNSvc.exe [10/11/2011 6:46 AM 245760]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MPKSLCDFA53D0
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-27 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 20:39]
.
.
------- Supplementary Scan -------
.
TCP: DhcpNameServer = 192.168.10.1
TCP: Interfaces\{30F4F4BD-9581-485C-8D47-7889B282CA43}: NameServer = 208.67.222.222,208.67.220.220
FF - ProfilePath - c:\documents and settings\Tad Palmer\Application Data\Mozilla\Firefox\Profiles\d4m1k4fi.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-12-28 20:25
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(840)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(1268)
c:\windows\system32\WININET.dll
c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-12-28 20:28:36
ComboFix-quarantined-files.txt 2011-12-29 01:28
ComboFix2.txt 2011-12-14 18:43
.
Pre-Run: 28,822,020,096 bytes free
Post-Run: 28,850,528,256 bytes free
.
- - End Of File - - F29460D3A4BC97B071BC7780F19CC167
Here is Qoobox quarantined files or at least all I could find. Had to go to run C:\Qoobox\ComboFix-quarantined-files.txt to find it.
2011-12-14 18:43:15 . 2011-12-14 18:43:15 260 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Notify-PFW.reg.dat
2011-12-14 18:40:47 . 2011-12-29 01:24:04 7,491 ----a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2011-12-14 18:35:42 . 2011-12-29 01:20:18 102 ----a-w- C:\Qoobox\Quarantine\catchme.log